2005-05-03 23:33:09 +02:00
|
|
|
Shorewall 2.3.0
|
2005-04-08 20:07:58 +02:00
|
|
|
|
|
|
|
-----------------------------------------------------------------------
|
2005-05-03 23:33:09 +02:00
|
|
|
Problems corrected in version 2.3.0
|
2005-04-08 20:07:58 +02:00
|
|
|
|
2005-05-03 23:33:09 +02:00
|
|
|
None.
|
2005-04-11 01:08:21 +02:00
|
|
|
|
2004-01-31 20:06:39 +01:00
|
|
|
-----------------------------------------------------------------------
|
2005-05-03 23:33:09 +02:00
|
|
|
New Features in version 2.3.0
|
2004-12-14 17:11:49 +01:00
|
|
|
|
2005-05-03 23:33:09 +02:00
|
|
|
1) Shorewall 2.3.0 supports the 'cmd-owner' option of the owner match
|
|
|
|
facility in Netfilter. Like all owner match options, 'cmd-owner' may
|
|
|
|
only be applied to traffic that originates on the firewall.
|
2004-12-14 17:11:49 +01:00
|
|
|
|
2005-05-03 23:33:09 +02:00
|
|
|
The syntax of the USER/GROUP column in the following files has been
|
|
|
|
extended:
|
2004-12-14 17:11:49 +01:00
|
|
|
|
2005-05-03 23:33:09 +02:00
|
|
|
/etc/shorewall/accounting
|
|
|
|
/etc/shorewall/rules
|
|
|
|
/etc/shorewall/tcrules
|
|
|
|
/usr/share/shorewall/action.template
|
2004-12-19 17:52:13 +01:00
|
|
|
|
2005-05-03 23:47:34 +02:00
|
|
|
To specify a command, prefix the command name with "+".
|
2004-12-19 17:52:13 +01:00
|
|
|
|
2005-05-03 23:33:09 +02:00
|
|
|
Examples:
|
2004-12-19 17:52:13 +01:00
|
|
|
|
2005-05-03 23:47:34 +02:00
|
|
|
+mozilla-bin #The program is named "mozilla-bin"
|
|
|
|
joe+mozilla-bin #The program is named "mozilla-bin" and
|
2005-05-03 23:33:09 +02:00
|
|
|
#is being run by user "joe"
|
2005-05-03 23:47:34 +02:00
|
|
|
joe:users+mozilla-bin #The program is named "mozilla-bin" and
|
2005-05-03 23:33:09 +02:00
|
|
|
#is being run by user "joe" with
|
|
|
|
#effective group "users".
|
2004-12-19 17:52:13 +01:00
|
|
|
|
2005-05-03 23:33:09 +02:00
|
|
|
Note that this is not a particularly robust feature and I would
|
|
|
|
never advertise it as a "Personal Firewall" equivalent. Using
|
|
|
|
symbolic links, it's easy to alias command names to be anything you
|
|
|
|
want.
|
2005-01-03 18:27:46 +01:00
|
|
|
|
2005-01-10 17:36:08 +01:00
|
|
|
|